1.10.1 (L1) Ensure 'Blocks external extensions from being installed' is set to 'Enabled'

Information

This policy setting determines whether external extensions (an extension that is not installed from the Chrome Web Store) can be installed.

The recommended state for this setting is: Enabled.

Allowing users to install extensions from locations other than the Chrome Web Store can lead to unknown or malicious extensions being installed.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled :

Computer Configuration\Polices\Administrative Templates\Microsoft Edge\Extensions\Blocks external extensions from being installed

Impact:

Users will not be able to install extensions that do not originate form the Chrome web store.

See Also

https://workbench.cisecurity.org/benchmarks/24354

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(2), 800-53|CM-8(3), 800-53|CM-10, 800-53|CM-11, CSCv7|7.2

Plugin: Windows

Control ID: 9b6533a671ba726c0ffa3d3bfb9d88c939efa5988abf371a6eb71d6e0884d08c